GBHackers

Critical VMware vCenter Flaws Let Remote Attackers Bypass Authentication and Execute Code


Broadcom has released important security updates addressing critical vulnerabilities in VMware that could allow remote attackers to bypass vCenter authentication or execute arbitrary code.

These vulnerabilities, outlined in advisory VMSA-2026-0006, affect a range of products including vCenter, ESX, Workstation, Fusion, VMware Cloud Foundation, vSphere Foundation, and selected Telco Cloud products.

The advisory, published on July 29, 2026, covers five vulnerabilities with CVSS v3 scores ranging from 2.7 to 9.8. Organizations should prioritize remediation because no workarounds are available for the two critical issues related to vCenter.

Critical VMware vCenter Flaws

The most severe vulnerability is CVE-2026-59309, which is an authentication bypass in the VMware Directory Service. A remote, unauthenticated attacker with network access to a vulnerable vCenter Server can bypass authentication controls and gain unauthorized access to the management platform.

Since vCenter centrally manages ESXi hosts, virtual machines, permissions, templates, and infrastructure workflows, a compromise could provide an attacker with a highly valuable foothold in a virtualized environment. Organizations should treat internet-exposed or poorly segmented vCenter deployments as urgent patching priorities.

The second critical vulnerability is CVE-2026-59310, a directory traversal flaw in the vCenter Syslog server. Broadcom indicates that an attacker with network access may exploit this flaw to execute arbitrary code, posing a significant risk of remote code execution on the vCenter appliance.

Both of these vulnerabilities carry a maximum CVSS v3 score of 9.8 and require no privileges or user interaction, according to their published CVSS vectors.

Vulnerabilities Addressed

  • CVE-2026-59309 – Critical, CVSS 9.8: Authentication bypass in VMware Directory Service affecting vCenter. A network-based attacker may bypass authentication and gain unauthorized system access.
  • CVE-2026-59310 – Critical, CVSS 9.8: Directory traversal in the vCenter Syslog server. A remote attacker with network access may execute arbitrary code.
  • CVE-2026-47876 – Critical, CVSS 9.3: Out-of-bounds write in the VMXNET3 virtual network adapter in VMware ESX. An attacker with local administrator privileges in a VM using VMXNET3 could execute code on the ESX host, effectively enabling a VM escape scenario. Non-VMXNET3 adapters are not affected.
  • CVE-2026-41703 – Important, CVSS 7.6: Out-of-bounds read affecting ESX, Workstation, and Fusion. An attacker with VM deployment privileges could potentially disclose information or cause a host-process denial-of-service; on Workstation and Fusion, the impact is limited to information disclosure.
  • CVE-2026-41709 – Low severity, CVSS 2.7: Insufficient logging in ESXi. A malicious administrator may perform certain operations without those actions being properly recorded in logs.

Patching Guidance

Broadcom advises organizations to apply the fixed versions listed in the VMSA-2026-0006 response matrix:

  • vCenter fixes include version 9.1.0.0300 for 9.1 deployments, 9.0.2.0100 for 9.0 deployments, and vCenter Server 8.0 U3k for version 8.0.
  • For ESX, organizations should deploy ESXi-9.1.0.0200-25557999, ESXi-9.0.2.0100-25595025, or ESXi 8.0 U3k as applicable. VMware Cloud Foundation 5.x users must use the asynchronous patching process, while Telco Cloud customers should follow Broadcom KB449886.

Security teams should also restrict vCenter management interfaces to dedicated administrative networks, review privileged vCenter and ESXi accounts, and monitor for unusual authentication activity, new administrator accounts, configuration changes, or unexpected VMXNET3-related host events.

ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.



Source link